Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Is it possible to index and forward a specific sourcetype from an indexer?

$
0
0
I have a situation in which I need to get events from our Windows servers to a third-party device for a managed security provider. We have been doing this on the universal forwarder layer with mixed success. At the moment, the events get to the third party device and our two indexers, but field extractions are totally broken for the Windows security events. The universal forwarders also use props and transforms on the data going out to the third party device to ensure it is formatted correctly for our managed security provider (which is where I suspect the field extractions are going wrong). What I would like to do is forward these events from the indexers instead to make managing this situation a bit easier (forwarding to the third party device from a single point, rather than a hundred disparate points across our network). Essentially what I want is this: 1) Universal forwarder forwards all Windows logs to our indexers as normal 2) The indexers index everything, but then forward Windows security event logs (formatted via props and transforms for our security provider) to the third party device Is this possible?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>